41+ standards, regulations and management frameworks used in active practice — spanning AI governance, security, privacy, data-centre infrastructure, enterprise risk and delivery.
Risk-based AI regulation addressing prohibited practices, high-risk systems, transparency and general-purpose AI obligations across the AI lifecycle.
AI-specific risk management — identification, assessment, treatment, monitoring and communication of risks arising from AI systems.
Artificial intelligence management systems — organizational accountability, AI policies, lifecycle governance, risk management and continuous improvement.
The Govern, Map, Measure and Manage approach for identifying and controlling risks arising from AI systems.
Governance considerations for generative AI and foundation-model applications, including risks from model outputs, data, security and human interaction.
Responsible AI development and deployment principles — human-centred values, transparency, robustness, accountability and sustainable innovation.
Business-continuity management addressing organizational resilience, business-impact analysis, continuity strategy, response and recovery.
ICT readiness for business continuity — connecting IT infrastructure with organizational resilience.
Data-centre facilities and infrastructure standards addressing power, environmental control, telecommunications and security.
Telecommunications infrastructure standard for data centres — site infrastructure, telecommunications, electrical and mechanical requirements.
Data-centre resilience and topology concepts across Tier I through Tier IV, including redundancy and fault-tolerance considerations.
Iterative delivery practices — product backlogs, sprint-based development, stakeholder feedback and continuous product improvement.
Integration of development, infrastructure, security and operations into a single delivery lifecycle.
Operational lifecycle for machine-learning and AI systems spanning deployment, monitoring, governance and continuous improvement.
Project-management body of knowledge — scope, schedule, cost, quality, resources, communications, risk and stakeholder management.
Enterprise-risk concepts connecting strategy, performance, governance, risk and organizational decision-making.
Internal-control concepts spanning control environment, risk assessment, control activities, information/communication and monitoring.
Risk-management principles for systematic identification, analysis, evaluation, treatment, monitoring and communication of enterprise risk.
Governance model distinguishing responsibilities across operational management, risk/compliance oversight and independent assurance.
Technology-governance framework connecting enterprise objectives with IT governance, risk, controls, performance and value delivery.
Board and executive-level principles for effective governance and organizational use of information technology.
British Columbia Personal Information Protection Act — provincial privacy requirements for private-sector organizations.
India's data-protection law — data fiduciary responsibilities, consent, data-principal rights, security safeguards and breach obligations.
General Data Protection Regulation
Privacy Information Management System — extends ISO 27001 for PII processing.
Technology-law framework for electronic systems, cybersecurity, digital information and intermediary/technology operations in India.
Canadian federal privacy law governing the collection, use, disclosure and safeguarding of personal information.
Process-based quality-management concepts covering customer focus, leadership, process management and continual improvement.
Prioritized cybersecurity practices addressing assets, identities, vulnerabilities, access, monitoring and recovery.
Information security management system requirements and Annex A controls.
Information security control guidance spanning organizational, people, physical and technological security.
Cloud-specific information-security controls applicable to cloud service providers and customers.
Protection of personally identifiable information processed within public-cloud environments.
Cybersecurity risk management across Govern, Identify, Protect, Detect, Respond and Recover.
Security and privacy control concepts applicable to enterprise and government information systems.
Assurance expectations and control environments, particularly SOC 2 Trust Services Criteria around security, availability, processing integrity, confidentiality and privacy.
IT service management principles for planning, delivery, monitoring and continuous improvement of technology services.
Service-management concepts covering incident, problem, change, service-level, configuration, availability and capacity management.
Secure-development principles covering organizational preparation, software protection, secure production and vulnerability response.
Open-source software governance — component identification, licence obligations, approval processes and software supply-chain risk.
Application-security principles and common vulnerability frameworks relevant to web applications, APIs, authentication and data handling.